CVE-2026-77420: Jline JLINE3

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HISTORY_IGNORE configuration value into a Java regular expression while escaping only part of its syntax, allowing other regex metacharacters to reach the backtracking engine. An attacker who can control application or user configuration can supply a nested-quantifier expression that is reevaluated whenever a command is added to history, consuming excessive CPU and indefinitely blocking the reader thread. This issue is fixed in versions 3.30.15 and 4.3.1.

Affected products

  • Jline JLINE3: from 3.0.0, before 3.30.15 (fixed in 3.30.15); from 4.0.0, before 4.3.1 (fixed in 4.3.1)

Published 2026-09-23. Last modified 2026-09-30.